Build a list that converts.
Updated 25 September 2026 // by Mark Glazer, ReplyLead // editorial standards
The biggest lever on cold email is not the copy, it is who you send to. Here is how to build a B2B list of real, ICP-matched decision-makers that turns outreach into booked meetings.
- 95.8%of business-domain records have a first name, counted 25 September 2026
- 83.8%of business-domain records have a first name, company and job title
- 52.8%of business-domain records have all five: name, company, title, industry, city
- 30.0%of business-domain records have no city
The short answer: Build a cold email list in five steps: define a tight ICP from your best existing customers, source matching prospects from reliable providers, enrich them with firmographic detail, verify every address before sending, then segment so each cohort gets a message written for it. Relevance beats size: a smaller ICP-matched list outperforms a large generic one. In ReplyLead's own contact database, counted in full on 25 September 2026, 83.8% of business-domain records carry a first name, company and job title, and only 52.8% also carry an industry and a city - so plan the fallbacks before you write the merge fields.
You can write the best cold email in the world, but if it lands in the wrong inbox it will never work. Targeting is the multiplier on everything else, which is why a serious campaign starts with the list, not the copy. This is the process we use to build one.
How much of a list actually has your merge fields
Every merge field needs a value. We counted how many records in ReplyLead's own contact database carry each combination of six common merge fields. The share drops with every field you add: a first name is nearly always there (95.8%), while 30.0% of business-domain records have no city.
Estimate your own list
Interactive: how much of a list will have your merge fields?
Tick the fields your email needs.
83.8% of business-domain records in the ReplyLead database have every field you picked. At that rate, a list of 10,000 would have about 8,383 records with every field.
Rates are joint counts from ReplyLead's contact database (every record, counted 25 September 2026), not from your vendor; a list bought elsewhere will differ. Nothing you enter is stored or sent.
Which fields go missing, and what to write instead
Share of business-domain records in the same count with each field empty. Every merge field needs a fallback line for these records, or a separate segment. The fallbacks are ReplyLead's suggestions, not a standard.
| Field | Missing | Fallback that still reads naturally |
|---|---|---|
| Company name | 3.0% | Take the company from the website on the email domain, or write the line about the role instead. |
| First name | 4.2% | Use a greeting that needs no name, such as "Hi,", rather than a guessed one. |
| Team size | 13.3% | Leave size out of the copy, or put these records in a separate segment. |
| Job title | 13.4% | Write to the function (for example, whoever runs sales) and do not guess seniority. |
| Industry | 21.1% | Look it up on the company website before sending, or use a line that fits any industry. |
| City | 30.0% | Leave location out rather than risk an empty or wrong city. |
Five steps to a high-converting list.
Define a tight ICP
Start from your best existing customers and extract the shared traits: industry, company size, revenue, geography, tech stack, and the exact job titles that make buying decisions. The tighter the ideal customer profile, the more relevant every message and the higher the reply rate. Vague targeting is the root cause of most failed campaigns.
Source accurate data
Pull prospects that match the ICP from reliable data providers and public web sources. Coverage matters, but accuracy matters more, sources vary widely in quality, so treat everything as unverified until it is checked. Aim for real decision-makers, not role accounts or generic inboxes.
Enrich for relevance
Add the firmographic detail that makes personalization possible: industry, company description, location, website, and recent signals. Rich, accurate fields are what let copy speak to the recipient's actual business instead of sounding generic. This enrichment layer is where good targeting becomes great outreach.
Verify every address
Validate each email before it is ever sent. Bounces and spam-trap hits are among the fastest ways to wreck a sending domain's reputation and push future email into spam. Verification protects both your results and your deliverability.
Segment and prioritize
Group the list by segment so each cohort gets a message written for it, and prioritize the highest-fit accounts first. Segmentation turns one blast into several relevant conversations, and it is what makes split-testing meaningful. From here the list is ready for the rest of the campaign.
Mistakes that quietly kill lists.
xBuying generic lists
Stale, shared with countless senders, and rarely ICP-fit. They hurt relevance and deliverability at the same time.
xLoose targeting for volume
Widening the net to hit a number fills the list with people who will never buy, dragging down every metric that matters.
xSkipping verification
Unverified addresses mean bounces and spam traps, the fastest route to a damaged domain and inbox placement problems.
xNever refreshing data
People change roles and companies constantly. A list that is not maintained decays quickly and quietly loses accuracy.
Two of these mistakes have measured write-ups from our own operation: why a "verified" list still bounces (verification is a point-in-time answer, catch-alls say yes to everything, gateways answer with policy) and why the vendor's industry field is usually wrong (qualify from the company's own website, requeue failed lookups, never let an API error become a targeting decision). The operating rules we run lists against are published in our mechanics.
What decides whether a list delivers.
Most list-building guides stop at "find the right people and verify the emails." Two things that decide whether the list reaches the inbox at all are missing from almost all of them - and they are where a list quietly succeeds or fails.
1. Where the addresses sit, not just who they belong to. Deliverability is set by the recipient's mail provider as much as by your sending. A list that is mostly Microsoft 365 must be worked at a far lower daily pace than one that is mostly Google Workspace, and any address behind a security gateway is the hardest to reach of all. We measured that receiving landscape across 9,058,780 business domains and read a list's provider mix before it is finalised, so the sending plan matches the inboxes it is aimed at. No amount of verification fixes a list you are sending into too fast for its providers.
2. When you verify, not just whether. A "verified" flag from a data vendor describes the day the vendor checked, not the day you send - which is exactly why verified lists still bounce. Catch-all domains accept everything at verification time and can still reject the real send. We verify at the moment of use, per campaign, rather than trusting a flag attached weeks earlier at purchase.
The number a list-building method should be judged on. Across the 429,763 emails in our published campaign book, built to exactly this standard, the bounce rate was 1.32% - comfortably under the 2% ceiling at which bounces begin to damage the domains you send from. Delivery is not luck; it is the list.
We build the list and run the campaign.
List building is step one of a system. ReplyLead builds the ICP-matched, enriched, verified list and then runs the whole engine on top of it, copy, infrastructure, deliverability, and booked meetings, on a revenue-share model. See the full playbook, how pricing works, or estimate your ROI.
Every step above leans on a data vocabulary worth knowing precisely: firmographic data, the company attributes an ICP is written in; technographic data, what a target company runs, including the mail environment that decides how it filters your email; and lead enrichment, how a bare record becomes a contactable one. Each has its own working definition, failure modes included.
Common questions.
What makes a good B2B cold email list?
+
How do I define my ideal customer profile (ICP)?
+
Where does B2B prospect data come from?
+
Why is email verification important?
+
How large should a cold email list be?
+
Should I buy a prebuilt email list?
+
When this page does not apply
- You buy a list from a vendor. These rates describe ReplyLead's database, not yours; run the same count on your own file before writing merge fields.
- You send to consumers. The counts and the advice are for business outreach; consumer email has stricter rules.
- You need legal advice on list sources. See is cold email legal for the regulators' own words; this page is not legal advice.
- You need verified addresses. Completeness is not deliverability; a record with every field can still bounce. Verify before sending.
How this page was built and checked
The field counts are a read-only count of every record in ReplyLead's contact database on 25 September 2026. A business-domain address is one not on these 13 freemail domains: gmail.com, yahoo.com, hotmail.com, outlook.com, aol.com, icloud.com, live.com, msn.com, ymail.com, proton.me, protonmail.com, gmx.com, mail.com; addresses on other consumer or internet-provider domains still count as business-domain. The page publishes rates, not the size of the database. A field counts as present when it is not empty after trimming. The chart and the calculator use the exact number of records carrying each combination of the six fields, so they need no independence assumption. The five steps are ReplyLead's practice. ReplyLead runs cold email and LinkedIn outbound.
Sources and check dates
ReplyLead's own pages and data behind this one:
- Lead enrichment: how a bare record becomes a contactable one.
- Firmographic data: the company fields behind segmentation.
- What is a catch-all email domain?: why a complete record can still fail verification.
- Cold email statistics: reply and bounce rates from the same programmes.
Outside primary sources, each read on the date shown:
- FTC: CAN-SPAM Act, a compliance guide for business: US rules that apply to every address on a list, B2B included. checked 25 September 2026.
- ICO: electronic mail marketing (PECR): UK rules for emailing companies and sole traders. checked 25 September 2026.
- ICO: when can we rely on legitimate interests?: UK GDPR legitimate interests for business-to-business contacts. checked 25 September 2026.
- Canada's Anti-Spam Legislation, full text: consent and conspicuously published business addresses. checked 25 September 2026.
- Google: Email sender guidelines: authentication and spam-rate requirements that list quality feeds into. checked 25 September 2026.
- Yahoo Sender Hub: best practices: Yahoo's sender requirements. checked 25 September 2026.
From keyword match to account decision
A real prospecting signal, with its limits left visible
A company mentioning your product category is a research lead. To make it a useful prospecting record, preserve the observed fact, source and date separately from what you still need to establish.
Worked public-source example: security questionnaires
On 11 September 2026, GitLab's published customer assurance process describes customer security questionnaire requests and Field Security ownership. That establishes a documented workflow. It does not establish dissatisfaction, a software purchase, available budget or fit for your product. GitLab is a public research example, not a ReplyLead customer or endorsement.
- Observed fact
- The business documents a questionnaire-handling process.
- Useful relevance
- A seller of questionnaire workflow software can research the process and ownership instead of opening with a generic security pitch.
- Decision
- Research further. Do not label the account as buying or claim its current process is broken.
- What would change the decision?
- Evidence of an appropriate target segment and a relevant unmet workflow, followed by a conversation with the responsible owner. Otherwise exclude it from this campaign.
Use the same discipline across your list
The editable worksheet includes this public example, an illustrative dispatcher-role signal and an illustrative stale-vacancy exclusion. It separates observed evidence, unknowns and the next check, so a keyword match cannot silently turn into a qualified lead.
Download the evidence worksheet (.csv)
- Capture the company-owned source and the exact relevant observation.
- Record when you checked it and who or what the source actually describes.
- Apply company, role and product-fit exclusions before finding a contact.
- Recheck time-sensitive evidence before use. Keep an expired signal out until it is verified again.
- Write the message around a supported observation and a useful next step, not an invented pain point.
See the completed SaaS campaign sequences for messages and worksheets built around specific workflows. Use lead enrichment to fill missing fields without treating a vendor estimate as a confirmed fact.
Start with the right list.
Tell us your ICP and we will build the verified, enriched list and run the campaign on it. Revenue-share, so we win when you win.
Apply to work with us